CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42424
5.3 MEDIUM

Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially …

Sep 10, 2024
CVE-2024-44072
5.7 MEDIUM

OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends …

Sep 10, 2024
CVE-2024-7955
4.8 MEDIUM

The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Sep 10, 2024
CVE-2024-7891
4.8 MEDIUM

The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Sep 10, 2024
CVE-2024-7784
6.1 MEDIUM

During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS …

Sep 10, 2024
CVE-2024-6979
6.8 MEDIUM

Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts …

Sep 10, 2024
CVE-2024-6509
6.5 MEDIUM

Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to …

Sep 10, 2024
CVE-2024-6173
6.5 MEDIUM

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing …

Sep 10, 2024
CVE-2024-45504
6.5 MEDIUM

Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of …

Sep 10, 2024
CVE-2024-45285
5.4 MEDIUM

The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. …

Sep 10, 2024
CVE-2024-45283
6.0 MEDIUM

SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC …

Sep 10, 2024
CVE-2024-45281
5.8 MEDIUM

SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed …

Sep 10, 2024
CVE-2024-45280
4.8 MEDIUM

Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited …

Sep 10, 2024
CVE-2024-45279
6.1 MEDIUM

Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL …

Sep 10, 2024
CVE-2024-44121
4.3 MEDIUM

Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability …

Sep 10, 2024
CVE-2024-44120
4.7 MEDIUM

SAP NetWeaver Enterprise Portal is vulnerable to reflected cross site scripting due to insufficient encoding of user-controlled input. An unauthenticated attacker could craft a malicious …

Sep 10, 2024
CVE-2024-44117
5.4 MEDIUM

The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and …

Sep 10, 2024
CVE-2024-21528
5.9 MEDIUM

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

Sep 10, 2024
CVE-2024-0067
4.3 MEDIUM

Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list …

Sep 10, 2024
CVE-2024-45286
6.5 MEDIUM

Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized …

Sep 10, 2024
CVE-2024-44112
4.3 MEDIUM

Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled …

Sep 10, 2024
CVE-2024-44116
4.3 MEDIUM

The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to …

Sep 10, 2024
CVE-2024-44115
4.3 MEDIUM

The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify …

Sep 10, 2024
CVE-2024-44113
4.3 MEDIUM

Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On …

Sep 10, 2024
CVE-2024-42380
4.3 MEDIUM

The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data …

Sep 10, 2024
CVE-2024-42378
6.1 MEDIUM

Due to weak encoding of user-controlled inputs, eProcurement on SAP S/4HANA allows malicious scripts to be executed in the application, potentially leading to a Reflected …

Sep 10, 2024
CVE-2024-42371
5.4 MEDIUM

The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify …

Sep 10, 2024
CVE-2024-41729
4.3 MEDIUM

Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation …

Sep 10, 2024
CVE-2024-38270
5.3 MEDIUM

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel …

Sep 10, 2024
CVE-2024-8611
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. …

Sep 9, 2024
CVE-2024-27365
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, …

Sep 9, 2024
CVE-2024-44085
6.1 MEDIUM

ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) …

Sep 9, 2024
CVE-2024-27387
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is …

Sep 9, 2024
CVE-2024-27383
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is …

Sep 9, 2024
CVE-2024-27368
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, …

Sep 9, 2024
CVE-2024-27367
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, …

Sep 9, 2024
CVE-2024-27366
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, …

Sep 9, 2024
CVE-2024-27364
4.4 MEDIUM

An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, …

Sep 9, 2024
CVE-2023-50883
6.1 MEDIUM

ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling …

Sep 9, 2024
CVE-2024-7318
4.8 MEDIUM

A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds …

Sep 9, 2024
CVE-2024-7260
6.1 MEDIUM

An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick …

Sep 9, 2024
CVE-2024-42759
6.3 MEDIUM

An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

Sep 9, 2024
CVE-2024-24510
6.1 MEDIUM

Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.

Sep 9, 2024
CVE-2024-45406
5.5 MEDIUM

Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

Sep 9, 2024
CVE-2024-8605
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affects unknown code of the file /view/registration.php of the component Registration …

Sep 9, 2024
CVE-2024-8604
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of …

Sep 9, 2024
CVE-2024-8373
4.8 MEDIUM

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can …

Sep 9, 2024
CVE-2024-8372
4.8 MEDIUM

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a …

Sep 9, 2024
CVE-2024-8601
6.5 MEDIUM

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker …

Sep 9, 2024
CVE-2024-45203
4.3 MEDIUM

Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to …

Sep 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.